{"_id":"@certaworks/audit-replay-logger","name":"@certaworks/audit-replay-logger","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@certaworks/audit-replay-logger","version":"0.1.0","description":"Records explicitly logged agent decisions, tool calls, and state changes with local audit replay.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./mcp":{"types":"./dist/mcp/server.d.ts","import":"./dist/mcp/server.js"},"./http":{"types":"./dist/http/server.d.ts","import":"./dist/http/server.js"}},"bin":{"audit-replay-mcp":"dist/mcp/server.js","audit-replay-api":"dist/http/server.js"},"scripts":{"build":"tsc","typecheck":"tsc --noEmit","test":"npm run build && vitest run","test:unit":"vitest run","mcp":"node dist/mcp/server.js","serve":"node dist/http/server.js"},"devDependencies":{"@types/node":"^22.0.0","tsx":"^4.19.0","typescript":"^5.8.0","vitest":"^3.2.0"},"engines":{"node":">=18"},"license":"MIT","author":{"name":"CertaWorks Labs LLC"},"homepage":"https://certaworks.dev","bugs":{"url":"https://github.com/plantBase369/certaworks-site/issues","email":"blair.hall@certaworks.dev"},"repository":{"type":"git","url":"git+https://github.com/plantBase369/certaworks-site.git"},"publishConfig":{"access":"public"},"keywords":["certaworks","mcp","ai-agent","agent-safety","audit","replay","logging"],"_id":"@certaworks/audit-replay-logger@0.1.0","_nodeVersion":"24.11.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-TXxPL/39ui9pz81Zqti82SAWDUwSxtacCKaH1Sew+6vWggzdYrTe4BqcyYT0OI/UBmVy0IHby8ELMXJWI5YPUQ==","shasum":"851012b9f66a3cebec722ff4e50a0fe24ca888ad","tarball":"https://registry.npmjs.org/@certaworks/audit-replay-logger/-/audit-replay-logger-0.1.0.tgz","fileCount":18,"unpackedSize":96558,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD0LtWXjCktuGTkYy/9H+lms4p7RCL+5aMcSxdrWIjBGAIgVxf+cB2/ACQ2Qf+o/trz3/H5gV1lPFO6GmS9VcmnFig="}]},"_npmUser":{"name":"blairhall","email":"Blair.Hall@certaworks.dev"},"directories":{},"maintainers":[{"name":"blairhall","email":"Blair.Hall@certaworks.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/audit-replay-logger_0.1.0_1779947817920_0.5964228463988437"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-28T05:56:57.739Z","0.1.0":"2026-05-28T05:56:58.069Z","modified":"2026-05-28T05:56:58.316Z"},"maintainers":[{"name":"blairhall","email":"Blair.Hall@certaworks.dev"}],"description":"Records explicitly logged agent decisions, tool calls, and state changes with local audit replay.","homepage":"https://certaworks.dev","keywords":["certaworks","mcp","ai-agent","agent-safety","audit","replay","logging"],"repository":{"type":"git","url":"git+https://github.com/plantBase369/certaworks-site.git"},"author":{"name":"CertaWorks Labs LLC"},"bugs":{"url":"https://github.com/plantBase369/certaworks-site/issues","email":"blair.hall@certaworks.dev"},"license":"MIT","readme":"# Audit & Replay Logger\n\n**Type:** Local Logger / API / MCP / Dashboard\n\n**Value:** Records explicitly logged agent decisions, tool calls, state changes, messages, and errors so teams can replay and debug what happened locally.\n\n## Current Status\n\nComplete as a local SDK / MCP / HTTP logger slice. It persists explicitly logged events, supports replay/export, and provides local tamper-evidence through event and bundle hashes.\n\n## Shipped Local Scope\n\n- SDK logger for sessions, decisions, tool calls, tool results, state changes, messages, errors, and session end events\n- Durable local JSON audit store with configurable path\n- Event sequence numbers, timestamps, causal links, event hashes, and hash-chain continuity\n- Redaction for common sensitive fields such as tokens, secrets, passwords, credentials, authorization headers, and API keys\n- Replay filtering by sequence range, event type, and actor\n- Causal-chain lookup by event id\n- Exportable replay bundle with event hashes, causal chains, and bundle hash\n- Local HTTP API plus lightweight dashboard page\n- MCP tools for logging, replay, causal-chain lookup, export, and session listing\n- Package bins and subpath exports for SDK, MCP, and HTTP usage\n\n## Install And Run\n\n```bash\nnpm install\nnpm test\nnpm run mcp\nnpm run serve\n```\n\nAfter build, the package exposes:\n\n```bash\naudit-replay-mcp\naudit-replay-api\n```\n\n## Local Store\n\nBy default, the logger writes to:\n\n```text\n.audit-replay-logger/audit-log.json\n```\n\nOverride with either:\n\n```bash\nAUDIT_REPLAY_LOGGER_STORE_PATH=/path/to/audit-log.json\nAUDIT_REPLAY_LOGGER_STORE=/path/to/audit-log.json\n```\n\nPass `storePath: null` to `createAuditLogger` only when you intentionally want an in-memory logger.\n\nMCP bundle exports are confined to a local export directory. By default that is:\n\n```text\n.audit-replay-logger/exports\n```\n\nOverride with:\n\n```bash\nAUDIT_REPLAY_LOGGER_EXPORT_DIR=/path/to/exports\n```\n\n## SDK Surface\n\n```ts\nimport { createAuditLogger } from '@blair/audit-replay-logger';\n\nconst audit = createAuditLogger({ storePath: './audit-log.json' });\nconst session = audit.startSession({ actor: 'agent', metadata: { task: 'refund-review' } });\n\nconst decision = audit.logDecision(session.id, {\n  actor: 'agent',\n  decision: 'request human review',\n  reasoning: 'confidence gate returned review'\n});\n\naudit.logToolCall(session.id, {\n  actor: 'agent',\n  tool: 'confidence_gate',\n  input: { action: 'refund customer', token: 'will be redacted' },\n  causedBy: decision.id\n});\n\nconst timeline = audit.replay(session.id);\n```\n\n## HTTP API\n\n```text\nGET  /dashboard\nGET  /health\nPOST /api/sessions\nGET  /api/sessions\nGET  /api/sessions/:id\nPOST /api/sessions/:id/events\nGET  /api/sessions/:id/replay\nGET  /api/sessions/:id/causal-chain/:eventId\nGET  /api/sessions/:id/bundle\n```\n\nThe server binds locally by default when run through:\n\n```bash\nnpm run serve\n```\n\n## MCP Tools\n\n- `start_session`\n- `end_session`\n- `log_event`\n- `log_decision`\n- `log_tool_call`\n- `log_tool_result`\n- `log_state_change`\n- `replay_session`\n- `causal_chain`\n- `list_sessions`\n- `export_bundle`\n\n## Current Limits\n\n- This is a local product slice, not hosted SaaS.\n- The logger records events explicitly sent through the SDK, MCP tools, or local HTTP API; it does not automatically observe every agent action.\n- Hashes and bundle hashes provide local tamper evidence, not a notarized compliance ledger.\n- There is no public npm publication, live checkout, user auth, team workspace, hosted retention policy, signed export, WORM storage, or compliance certification yet.\n- The dashboard is a lightweight local API landing page, not a full visual replay timeline UI.\n\n## Verification\n\nFresh suite verification on 2026-05-28:\n\n- `npm test` passed, 25/25 SDK, persistence, redaction, MCP, HTTP, and package contract tests.\n- `npm run build` passes.\n- Package dry-run verifies only runtime artifacts and README are included.\n","readmeFilename":"README.md","_rev":"1-952114b989e0d5b45eb9bd1bd8fd815e"}